peter bassill · operator
$ cve CVE-2008-0396 JSON

CVE-2008-0396 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS8.53% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-01-23
Last modified2026-06-16

Affected (1)

VendorProduct
bitdefenderupdate server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD